Detection and monitoring EU-developed
Guardsix SIEM
Security information and event management product that correlates logs from hybrid infrastructure and provides detections, investigation context, and audit evidence.
By Guardsix · Denmark
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- Guardsix
- Recorded country
- Denmark
- Product model
- Commercial
- Deployment
- Self-hosted
- Software license
- Proprietary
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteGuardsix traces its SIEM to Danish Logpoint; its published history records a Danish startup acquisition behind the first SIEM. Current shareholders and all engineering locations are not established here.
Reported capabilities
- Collects logs across hybrid, on-premises, OT, and cloud environments.
- Supports self-hosted and air-gapped deployment.
- Formerly named Logpoint SIEM; the current Guardsix name is a rebrand.
Scope and limits
Vendor sovereignty statements are marketing claims, not independently verified ownership or legal conclusions. Command Centre is an umbrella name.
Inspect the research evidence 4 source observations
identity / capabilities / deployment
The current commercial SIEM page names the product, describes detections and log visibility, offers a demo and pricing context, and explicitly says self-hosted and air-gappable.
Read sourceidentity / maintenance
The FAQ maps Logpoint SIEM to Guardsix SIEM and explains that Command Centre is a portfolio umbrella, not a separately purchasable product.
Read sourceorigin / country
The company's own history places its founding in Denmark and says the original Logpoint SIEM followed acquisition of Danish startup Immune/LogEx.
Read sourcelicense
The current Guardsix EULA grants a paid nontransferable right to use SIEM and network-monitoring software, retains source and intellectual-property rights, and prohibits redistribution.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection